X
Contacted by us, but you never reached out to the ITRC? Ignore it - it’s a scam!
Skip to content
ITRC logo white final
ITRC-logo-color-final.svg

Support the ITRC

Business Login

Call Now 888.400.5530

  • Victim Help Center
  • Solutions

    Prevent Identity Theft

    Protect your identity from theft and misuse.

    Recover My Identity

    Get direct assistance, a custom remediation plan, and resources if you're a victim.

    Protect My Business

    Explore our business service offerings today.

    Breach Alert

    Get information on the latest data compromises.

    Additional Support

    Vulnerable populations can get additional support to help protect their identity.

  • Resources

    Insights

    Get the latest information on identity crimes.

    Newsletter

    Stay up-to-date on the latest news and happenings from the ITRC.

    Reports

    Explore independent surveys and studies from the ITRC.

    Podcasts

    Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    Events

    Explore upcoming events involving the ITRC.

    Newsroom

    Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact

TurboTax Breach Caused by Credential Stuffing

Date: 02/25/2019

Home Help Center TurboTax Breach Caused by Credential Stuffing

Intuit has announced that its consumer-centric TurboTax software has suffered a security breach. Credential stuffing practices, allowed thieves to access users’ accounts for popular online tax service. Similar events in 2014 and 2015 led to the compromise of a number of users’ accounts, and now another event has compromised untold numbers of users’ tax returns.

The method of attack was nearly identical to the previous events. Using a tactic known as “credential stuffing,” hackers were able to access the complete identities of undisclosed numbers of users by gaining access to their accounts and looking up their previously filed tax returns. Credential stuffing occurs when hackers use information that was garnered from a different source—such as a separate data breach of an unrelated company—to test out the credentials in other places.

For example, if there’s a data breach of a bank or retailer that you use, your username and password that were stolen in that breach will be tested out on other websites. The entire database of compromised information, sometimes millions of separate entries, will be tried automatically. With many stolen consumer records to choose from, the chances that some of those credentials will work on one or more other websites are very, very high.

That is exactly what happened with the TurboTax breach. Any clients who reused their usernames and passwords from a previously breached site accidentally handed access to their TurboTax accounts—and therefore, their tax returns and complete identities—to the hackers.

Intuit has already filed a notice of the TurboTax breach with the Vermont attorney general’s office and has begun notifying affected customers. You will receive notice via email if your account was compromised. According to US law, Intuit must provide a number of services to those customers, including a year of free credit monitoring. It is important that you follow the instructions in the notification in order to unlock your TurboTax account and take advantage of the tools the company is offering to protect you from further harm.

More importantly, this event stands as yet another dire warning to consumers. Whether a consumer was impacted by this breach or not, they need to stop reusing passwords on multiple websites. Credential stuffing is easy to accomplish, regardless of the criminal’s level of technology know-how. Entire databases of compromised records are available for sale on the dark web, meaning anyone with the means can simply purchase login credentials and use them to steal information from other accounts. Keep your passwords long and unguessable, change them routinely to avoid situations just like this one, and make sure you are not reusing your passwords on multiple sites.


Contact the Identity Theft Resource Center for toll-free, no-cost assistance at (888) 400-5530. For on-the-go assistance, check out the free ID Theft Help App from ITRC.

Read next: The How and Why of Tax Identity Theft

How much information are you putting out there? It’s probably too much. To help you stop sharing Too Much Information, sign up for the In the Loop.

Get ID Theft News

Stay informed with alerts and newsletters from the Identity Theft Resource Center.

Global 100 2026 awards logo
ITRC 2026 Merit Award Winner
candid seal platinum 2026
Charity Navigator Badge Logo
Facebook-f X-twitter Youtube Linkedin-in Instagram
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Privacy Policy
  • Live Chat Policy
  • Accessibility
© Copyright 2026 – Identity Theft Resource Center

This website was supported in part by grant number 15POVC-21-GK-01092-NONF and 15POVC-22-GK-01803-NONF, awarded by the Office for Victims of Crime, Office of Justice Programs, U.S. Department of Justice. The opinions, findings, and conclusions or recommendations expressed in this product are those of the contributors and do not necessarily represent the official position or policies of the U.S. Department of Justice. View more about our copyright info here.

  • Victim Help Center
  • Solutions
    • Prevent Identity Theft

      Protect your identity from theft and misuse.

    • Recover My Identity

      Get direct assistance, a custom remediation plan, and resources if you’re a victim.

    • Protect My Business

      Explore our business service offerings today.

    • Breach Alert

      Get information on the latest data compromises.

    • Additional Support

      Vulnerable populations can get additional support to help protect their identity.

  • Resources
    • Insights

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Newsletter

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Reports

      Explore independent surveys and studies from the ITRC.

    • Podcasts

      Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    • Events

      Explore upcoming events involving the ITRC.

    • Newsroom

      Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact


  • Call Now 888.400.5530